Bash Shellshock Bug

You might have heard a fair bit in the news recently about the Bash Shellshock bug, which is the second major bug (alongside the OpenSSL Heartbleed bug) to hit the computing world this year. Heartbleed was a major security threat that could potentially allow an attacker to view a large amount of private data that would normally be safely encrypted, but it did not actually allow an attacker to directly take over a computer. The Shellshock bug, on the other hand, is a more major exploit that actually allows the attacker to take unauthorized control of an affected system and, with a complexity of exploitation rating of "low" given to it by Internet security firm Rapid7, it is not difficult for a hacker to take advantage of the Shellshock exploit. This bug effects any Unix-like operating system that makes use of Bash (Bourne-again shell) as its command-line interpreter, which includes Raspbian, Mac OS X, and a large number of Linux distributions. As the vast majority of websites out there run on Linux-based operating systems, this problem is a serious global issue. Perhaps the most surprising thing is that the bug has been present in Bash for 25 years since version 1.03! The good news for all of you Raspberry Pi users is that this is only really a security issue if your device is visible to the wider Internet and not just to your local area network (LAN). In any case, it is a good idea to fix the issue, and a patch has already been deployed to the Raspberry Pi repositories. You can get this patch by simply running an update in the usual manor:

sudo apt-get update
sudo apt-get upgrade

Eben Talks Display and Model A+

Eben Upton attended the recent Europe 2014 edition of the TechCrunch Disrupt series, which was held in Old Billingsgate in London. The Raspberry Pi founder brought with him an add-on board the Raspberry Pi Foundation and its associated partners have been talking about for months – the official display board. In the on-stage interview with TechCrunch's John Biggs, Upton confirms the device will include an 800x480 pixel WVGA (Wide VGA) display, complete with a 10-point capacitive touch screen interface. The interface board with the screen appears to have shrunk since the first iteration we saw in Manchester earlier this year, and it takes a shape similar to the HAT specification. Despite the HAT shape, the new device does not actually interface over the GPIO header but connects via the dedicated DSI connector, which, until now, has had no purpose. It has mount points that correspond to the new Model B+ and appears to actually mount underneath the Raspberry Pi. Upton doesn't mention a price yet, but he hints that the display will be available for purchase towards the end of 2014 or beginning of 2015. He also talks briefly about the Model A+, mentioning that the foundation hopes to make an announcement soon and that they think the A+ will be an "exciting product" that will "capture people's imaginations." [11].

Buy this article as PDF

Express-Checkout as PDF

Pages: 4

Price $2.95
(incl. VAT)

Buy Raspberry Pi Geek

SINGLE ISSUES
 
SUBSCRIPTIONS
 
TABLET & SMARTPHONE APPS
Get it on Google Play

US / Canada

Get it on Google Play

UK / Australia

Related content

  • The Pi Wire

    Things move quickly in the Raspberry Pi ecosystem. This regular column rounds up the best Raspberry Pi and open hardware news to keep you up to date on the latest projects, products, and events.

  • Interview: Raspbmc maintainer Sam Nazarko

    A 19-year-old student has launched the most popular media center distribution for the Raspberry Pi. Read on for the story of Raspbmc and Sam Nazarko.

  • Testing the new Raspberry Pi touchscreen display

    The new Rasp Pi display provides a compact option for viewing screen output – and it comes at a Pi-like low price of only $60.

  • The Pi Wire

    As with everything in the technology industry, things move pretty quickly in the Raspberry Pi ecosystem – so much so that it can be really hard to keep up sometimes! This regular column looks to round up the best Raspberry Pi and open source hardware news to keep you up to date on the latest developments, projects, and products.

  • The Pi Wire

    The Raspberry Pi 3 arrives; a new Debian-based Linux operating system for Raspberry Pi; a new release of the Google-sponsored Chromium OS for Raspberry Pi 2 is available for download; Pi in Space; and a bad trojan threatens Android devices.